FaceTime for Mac Beta Opens Up Security Hole to Allow for Compromised Apple IDs
![]()
The primary issue appears to be FaceTime for Mac's display of account information, which reveals the user's date of birth and security question and answer for their account once signed in with their Apple ID, with no secondary request for password authentication. Consequently, anyone with physical access to a user's machine could view that information, which can then be used to reset the password for the account without requiring any email or other confirmation. The password can also be reset directly within the FaceTime application without a requirement that the current password be entered.
And while a user should in theory be able to address this issue by signing out of their account in FaceTime, the application automatically remembers the account details for the last-used account and pre-populates them the next time the application is opened or a sign-in is attempted.
Obviously there are any number of ways that sensitive information could be viewed or compromised by individuals with physical access to a user's machine, but the FaceTime application seems to make such actions remarkably easy, making private account reset information plainly visible at any point after initial log-in to the service.
Update: Apple appears to have addressed the issue on its end, as users are reporting that attempting to select the "View Account" option in FaceTime for Mac's preferences now briefly takes them to a blank window before bouncing them back to the selection page and offering no ability to view the account information.
Top Rated Comments
(View all)21 months ago
So don't leave your computer around people you don't trust. If you do, leave it password protected. Who really cares?
ThaYankees1903 :apple:
ThaYankees1903 :apple:
21 months ago
While it's no excuse for lax programming, this is BETA software and is therefore bound to contain issues such as this.
I hope they filed a bug report with Apple...
I hope they filed a bug report with Apple...
21 months ago
I wonder who's going to blow this one out of proportion. If someone has free access to your computer, logged in, to view any information they please, odds are your security problems are going to be much bigger unless you're rather paranoid or careful. Apple will probably touch this little bit up in the beta process.
21 months ago
Wow, fail! I'm glad I think Facetime is worthless and will never use it... :rolleyes:
21 months ago
guess that is why it is beta.
Yup. But this is a huge security flaw. I will stay away from this until everything is sorted.
[ Read All Comments ]

Our sister-site TouchArcade notes that Chillingo's excellent physics puzzler Feed Me Oil is free today for both the iPhone and iPad. It's normally $0.99 for iPhone and $1.99 for iPad....
Several years ago, Comcast began instituting bandwidth caps of 250GB per month on its residential customers. In 2008, this was plenty for most customers, but with the advent of streaming video...
Reuters reports that China Mobile Chairman Xi Guohua has once again publicly stated that the world's largest mobile phone carrier is engaged in talks with Apple about offering the iPhone to its...
Apple has filed a motion to dismiss in a case filed by customers over alleged misleading advertising depicting the Siri technology in the iPhone 4S. The lawsuit, filed in March, alleges that...
The American Customer Satisfaction Index (ASCI) today released its latest rankings of customer satisfaction in the United States for mobile phones and a number of products and services, with the new...